All 7 CVE vulnerabilities found in HTTP Headers, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4132 | HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters CWE-73 | 7.2 | High | 2026-04-22 |
| CVE-2026-2717 | HTTP Headers <= 1.19.2 - Authenticated (Administrator+) CRLF Injection via Custom Header Values CWE-93 | 5.5 | Medium | 2026-04-22 |
| CVE-2026-1379 | HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting CWE-79 | 4.4 | Medium | 2026-04-22 |
| CVE-2023-37978 | WordPress HTTP Headers Plugin <= 1.18.11 is vulnerable to Server Side Request Forgery (SSRF) CWE-918 | 4.4 | Medium | 2023-11-13 |
| CVE-2023-37874 | WordPress HTTP Headers Plugin <= 1.18.11 is vulnerable to Cross Site Scripting (XSS) CWE-79 | 5.9 | Medium | 2023-08-05 |
| CVE-2023-1208 | HTTP Headers < 1.18.11 - Admin+ Remote Code Execution | 9.8 | - | 2023-07-10 |
| CVE-2023-1207 | HTTP Headers < 1.18.8 - Admin+ SQL Injection | 9.8 | - | 2023-05-15 |
All 7 known CVE vulnerabilities affecting HTTP Headers with full Chinese analysis, references, and POCs where available.